CVE-2026-7141: Vllm Kv Cache Uninitialized Resource

KV cache blocks for FullAttention models are not zeroed due to incomplete logic in needs_kv_cache_zeroing.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-7141-vllm-kv-cache-uninitialized-resource --engine opengrep

Description

KV cache blocks for FullAttention models are not zeroed due to incomplete logic in needs_kv_cache_zeroing.